CVE-2026-25724Disclosure(anthropic / claude_code)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch anthropic claude_code systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Claude Code is an agentic coding tool. Prior to version 2.1.7, Claude Code failed to strictly enforce deny rules configured in settings.json when accessing files through symbolic links. If a user explicitly denied Claude Code access to a file (such as /etc/passwd) and Claude Code had access to a symbolic link pointing to that file, it was possible for Claude Code to read the restricted file through the symlink without triggering deny rule enforcement. This issue has been patched in version 2.1.7.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-61CWE-285

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • claude_code

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-02-06); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
claude_code

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-02-06: 1Mentions · 2026-02-08: 1Mentions · 2026-05-21: 1Patch / Workaround · 2026-05-21: 1Technical Details · 2026-02-06: 1Technical Details · 2026-05-21: 102-0602-0805-21
Signal classification3 categories
Disclosure
133.3%
General
133.3%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-061
Disclosure1
2026-02-081
General1
2026-05-211
Patch1
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-25724 Claude Code is an agentic coding tool. Prior to version 2.1.7, Claude Code failed to strictly enforce deny rules configured in settings.json when accessing files thro… https://www.cve.org/CVERecord?id=CVE-2026-25724

    Post summary

    Claude Code before v2.1.7 did not enforce deny rules set in settings.json for file access, indicating a potential vulnerability (CVE‑2026‑25724).

    80010173
    56.5K followersView on X
  • Martin Musiol@musiol_martin
    Patch

    CVE-2026-25724: a malicious repo can aim @AnthropicAI's Claude Code at a symlink and walk its file reads into ~/.ssh or .env. Patched in 2.1.7. Every coding agent treats your filesystem as trusted. Pin the version, isolate the runtime. https://aigeneral.net

    Post summary

    CVE-2026-25724 allows a malicious repo to read ~/.ssh or .env via symlink manipulation in Anthropic's Claude. The issue is fixed in 2.1.7, and no active exploitation is reported.

    0000057
    398 followersView on X
  • cvereports@_cvereports
    General

    CVE-2026-25724: The Symlink Whisperer: Bypassing Claude Code's Security Rails In the race to build autonomous coding agents, developers often forget the oldest tricks in the UNIX book. Claude Code, Anthropic's CLI tool for agentic coding, implemented ... https://cvereports.com/reports/CVE-2026-25724

    Post summary

    A headline and link to a report announcing CVE‑2026‑25724, without any additional detail on PoC, exploitation, patch, or technical specifics.

    0000057
    27 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appanthropicclaude_code-node.js-

Explore more